ZoneDeck

Free · Open signup · For AI agents

Free authoritative DNS, built for AI agents

Sign up and connect any domain — or any subdomain (dev.example.com). Hand AI agents a fine-grained token instead of your whole Cloudflare account: zones, records and certificates run end-to-end with no human in the loop.

zonedek — operator console

// capabilities

Why ZoneDeck

Any domain, any subdomain

Not just registrable domains: a subdomain at any depth (dev.example.com) can be hosted as its own zone — one NS delegation from the parent and you are done.

Safe AI-agent isolation

Give agents a scoped token, not your entire Cloudflare account: they only see their own zones, permissions are per-checkbox, every change is audited.

Zero-touch automation

Add a zone, create records, issue a certificate — the whole chain runs over API/MCP with no human steps.

Built-in MCP server

A Streamable HTTP MCP endpoint ships built in: Claude and other clients connect with one config snippet and drive DNS through native tools.

Multi-node authoritative DNS

Zones live on the primary and sync to every secondary automatically; you never touch the plumbing.

ACME DNS-01 certificates

Issue and renew wildcard certificates with acme.sh / certbot through a minimal-scope token.

Vanity nameservers

Serve any zone from your own branded ns1/ns2 hostnames — glue records handled for you.

Fine-grained tokens + audit

Scope-by-scope authorization (zones/records/dns01/repair…), tokens confined to their own account, full audit on every action.

Free, no strings

Everything on this page is free. The interface ships in English, 简体中文 and 繁體中文.

// how it lands

*.example.com wildcard certificate issued · Agent created www A 203.0.113.10 via MCP

Indie developersPoint a side project at multi-node authoritative DNS — an apex domain or a dev.example.com subdomain alike; signup is instant and it costs nothing.
AI agent workflowsHand the token to Claude or GPT and manage records from a chat — never your whole Cloudflare account: a scoped token is the entire grant, via MCP or REST, with every step audited.
Certificate automationRenew *.example.com wildcards via ACME DNS-01 with a dns01-only token; one line hooks it into acme.sh — challenge publish to TXT cleanup runs over the API, no human needed.
Home broadband & homelabNo fixed IP? A one-line DDNS client keeps your domain on your NAS wherever your IP roams.
Self-hosting & white-label NSServe DNS under your own ns1/ns2 hostnames with automatic glue — your brand, not ours.
Teams & environmentsSplit production, staging and internal services across accounts with per-scope tokens and a full audit trail.

// api-first

Built for developers and AI agents

A complete REST API with fine-grained tokens: records, certificates, DDNS — all scriptable. The docs cover every endpoint and include a copy-paste prompt for AI agents.

curl — dns.us.wr.rs
# list the zones this token owns
curl -s https://dns.us.wr.rs/api/v1/zones \
  -H "Authorization: Bearer dcp_xxx"

# add a record — or hand the job to your AI agent
curl -X POST https://dns.us.wr.rs/api/v1/zones/example.com/records \
  -H "Authorization: Bearer dcp_xxx" -H "Content-Type: application/json" \
  -d '{"name":"www","type":"A","value":"203.0.113.10"}'

The full API documentation →

Add your first domain now

Free registration, up and running in a minute.